Security Researcher (Associate) (Bengaluru)

Security Researcher (Associate) (Bengaluru)

24 Sep
|
Bytoid
|
Bengaluru

24 Sep

Bytoid

Bengaluru

Bytoid India Private Limited

Security Researcher (Associate)

Team: Information Security / GRC

Location: Bangalore / Hybrid / Remote

Experience: 0–2 years

Reports to: Security Manager / CISO

About the role

You'll split your time between hands-on security research and helping us build out our ISO 27001 Information Security Management System (ISMS). This is a role for someone early in their career who wants breadth: one week you might be tearing apart a vendor's product in a lab, the next you're mapping Annex A controls to what we actually do and chasing down evidence for an audit. You'll get mentorship from senior security engineers and a direct line to how a real certification programme gets built.

What you'll do

Security research

- Research, test, and benchmark security tools (vulnerability scanners, SAST/DAST, EDR, SIEM, secrets detection, cloud posture tooling) and write up clear recommendations on what we should adopt and why.
- Set up and run proof-of-concept deployments in a lab environment, including breaking things to see how the tooling responds.
- Track CVEs, advisories, and threat intelligence relevant to our tech stack; assess real-world impact and flag what needs action.
- Perform security reviews of third-party and open-source tools before they enter the environment, covering dependencies, permissions, data flows, and vendor security posture.
- Reproduce and validate published vulnerabilities in a controlled setting to understand exploitability in our context.
- Document findings in short, readable reports that a non-specialist stakeholder can act on.

ISO 27001 implementation support

- Support the rollout of the ISMS against ISO 27001:2022, including scoping, the Statement of Applicability, and the 93 Annex A controls.
- Draft and maintain policies, standards, procedures, and records under the guidance of the ISMS owner.
- Help maintain the risk register: assist with risk identification, assessment,



treatment plans, and periodic review.
- Collect, organise, and validate evidence for internal audits, management reviews, and external certification audits.
- Track corrective actions and nonconformities to closure, and chase control owners where needed.
- Assist with gap assessments, supplier security assessments, and security awareness training material.

What we're looking for
- 0–2 years in security, IT, or a related technical role. Internships, co-ops, lab work, CTFs, bug bounty, and serious self-study all count.
- Working understanding of core security concepts: the CIA triad, common vulnerability classes (OWASP Top 10), authentication and access control, encryption basics, and network fundamentals.
- Comfortable in Linux and with at least one scripting language (Python preferred) for automating repetitive analysis.
- Familiarity with ISO 27001, or with any comparable control framework (SOC 2, NIST CSF, CIS Controls). Deep experience isn't expected; genuine interest is.
- Solid written English. A good portion of this job is turning technical findings into documents other people can use.
- Organised and able to track many small open items without dropping them, which is most of what audit readiness is.
- Curiosity and a willingness to say "I don't know yet, let me go find out."

Nice to have
- Certifications such as ISO 27001 Foundation or Lead Implementer, CompTIA Security+, eJPT, or a cloud security associate cert.
- Exposure to cloud environments (AWS, Azure, or GCP) and CI/CD pipelines.
- Experience with a GRC platform, or with tools like Burp Suite, Nmap, Wireshark, Nessus/OpenVAS.
- A home lab, personal write-ups, CTF placings, or open-source contributions.

What we offer Competitive Salary along with perks.

How to apply

Submit your CV. If you have write-ups, a blog, a GitHub profile, or CTF results, include them. A short note about a security topic you've recently gone down a rabbit hole on is welcome and will be read.

📌 Security Researcher (Associate) (Bengaluru)
🏢 Bytoid
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security researcher (associate) (bengaluru) / bengaluru